2021-04-18 12:41:13 -07:00
|
|
|
// Copyright (c) 2015-2021 MinIO, Inc.
|
|
|
|
//
|
|
|
|
// This file is part of MinIO Object Storage stack
|
|
|
|
//
|
|
|
|
// This program is free software: you can redistribute it and/or modify
|
|
|
|
// it under the terms of the GNU Affero General Public License as published by
|
|
|
|
// the Free Software Foundation, either version 3 of the License, or
|
|
|
|
// (at your option) any later version.
|
|
|
|
//
|
|
|
|
// This program is distributed in the hope that it will be useful
|
|
|
|
// but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
// GNU Affero General Public License for more details.
|
|
|
|
//
|
|
|
|
// You should have received a copy of the GNU Affero General Public License
|
|
|
|
// along with this program. If not, see <http://www.gnu.org/licenses/>.
|
2018-10-09 14:00:01 -07:00
|
|
|
|
2019-10-01 15:07:20 -07:00
|
|
|
package openid
|
2018-10-09 14:00:01 -07:00
|
|
|
|
|
|
|
import (
|
|
|
|
"errors"
|
|
|
|
"fmt"
|
|
|
|
"sync"
|
|
|
|
)
|
|
|
|
|
|
|
|
// ID - holds identification name authentication validator target.
|
|
|
|
type ID string
|
|
|
|
|
|
|
|
// Validator interface describes basic implementation
|
|
|
|
// requirements of various authentication providers.
|
|
|
|
type Validator interface {
|
|
|
|
// Validate is a custom validator function for this provider,
|
|
|
|
// each validation is authenticationType or provider specific.
|
2021-09-13 16:22:14 -07:00
|
|
|
Validate(idToken, accessToken, duration string) (map[string]interface{}, error)
|
2018-10-09 14:00:01 -07:00
|
|
|
|
|
|
|
// ID returns provider name of this provider.
|
|
|
|
ID() ID
|
|
|
|
}
|
|
|
|
|
|
|
|
// ErrTokenExpired - error token expired
|
|
|
|
var (
|
2019-11-29 05:27:54 -08:00
|
|
|
ErrTokenExpired = errors.New("token expired")
|
2018-10-09 14:00:01 -07:00
|
|
|
)
|
|
|
|
|
|
|
|
// Validators - holds list of providers indexed by provider id.
|
|
|
|
type Validators struct {
|
|
|
|
sync.RWMutex
|
|
|
|
providers map[ID]Validator
|
|
|
|
}
|
|
|
|
|
|
|
|
// Add - adds unique provider to provider list.
|
|
|
|
func (list *Validators) Add(provider Validator) error {
|
|
|
|
list.Lock()
|
|
|
|
defer list.Unlock()
|
|
|
|
|
|
|
|
if _, ok := list.providers[provider.ID()]; ok {
|
|
|
|
return fmt.Errorf("provider %v already exists", provider.ID())
|
|
|
|
}
|
|
|
|
|
|
|
|
list.providers[provider.ID()] = provider
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
// List - returns available provider IDs.
|
|
|
|
func (list *Validators) List() []ID {
|
|
|
|
list.RLock()
|
|
|
|
defer list.RUnlock()
|
|
|
|
|
|
|
|
keys := []ID{}
|
|
|
|
for k := range list.providers {
|
|
|
|
keys = append(keys, k)
|
|
|
|
}
|
|
|
|
|
|
|
|
return keys
|
|
|
|
}
|
|
|
|
|
|
|
|
// Get - returns the provider for the given providerID, if not found
|
|
|
|
// returns an error.
|
|
|
|
func (list *Validators) Get(id ID) (p Validator, err error) {
|
|
|
|
list.RLock()
|
|
|
|
defer list.RUnlock()
|
|
|
|
var ok bool
|
|
|
|
if p, ok = list.providers[id]; !ok {
|
|
|
|
return nil, fmt.Errorf("provider %v doesn't exist", id)
|
|
|
|
}
|
|
|
|
return p, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
// NewValidators - creates Validators.
|
|
|
|
func NewValidators() *Validators {
|
|
|
|
return &Validators{providers: make(map[ID]Validator)}
|
|
|
|
}
|